PT-2026-8021 · Google · Google Chrome

Shaheen Fazim

·

Published

2026-01-01

·

Updated

2026-04-01

·

CVE-2026-2441

CVSS v2.0

10

High

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 145.0.7632.75/76 and 144.0.7559.75 (Linux)
Description Google Chrome has a high-severity use-after-free vulnerability (CVE-2026-2441) in the CSS engine that is actively exploited in the wild. This flaw allows attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. The vulnerability is related to CSS font feature values processing and can be triggered by visiting a malicious webpage. A public proof-of-concept (PoC) exploit is available. The vulnerability affects all Chromium-based browsers.
Recommendations Update Google Chrome to version 145.0.7632.75 or later on Windows and macOS, or to version 144.0.7559.75 or later on Linux. Restart the browser after applying the update.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-01947
CVE-2026-2441
OPENSUSE-SU-2026:10201-1
OPENSUSE-SU-2026:20248-1

Affected Products

Google Chrome